CVE-2013-0540
IBM WAS Liberty Profile <8.5.0.2 - Auth Bypass
Title source: llmDescription
IBM WebSphere Application Server (WAS) Liberty Profile 8.5 before 8.5.0.2, when SSL is not enabled, does not properly validate authentication cookies, which allows remote authenticated users to bypass intended access restrictions via an HTTP session.
Scores
EPSS
0.0012
EPSS Percentile
31.3%
Classification
CWE
CWE-287
Status
draft
Affected Products (2)
ibm/websphere_application_server
ibm/websphere_application_server
Timeline
Published
Apr 24, 2013
Tracked Since
Feb 18, 2026